CVE-2021-1871KEV · OVERDUE

Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

Critical · published April 2, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 93.7th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
7%
Percentile
93.7
In the wild
Confirmed
What it is

🚨 A sneaky logic flaw in Apple’s systems could let remote attackers execute code with just a simple trick. 🔥 Think of this as a hotel where the receptionist accidentally gives out master keys to random guests without proper checks. Anyone could wander into any room, accessing whatever they want with little effort! If exploited, an attacker could run arbitrary code on your device, possibly leading to total control over your system! This means they could access sensitive data, install malware, or even make your device act against your will. Absolutely devastating!

Put simply

Think of this as a hotel where the receptionist accidentally gives out master keys to random guests without proper checks. Anyone could wander into any room, accessing whatever they want with little effort! This vulnerability arises from insufficient restrictions due to a logic issue, allowing attackers to bypass security mechanisms and run unauthorized code remotely.

What to do

If exploited, an attacker could run arbitrary code on your device, possibly leading to total control over your system! This means they could access sensitive data, install malware, or even make your device act against your will. Absolutely devastating! Immediately update to macOS Big Sur 11.2, Security Update 2021-001 for Catalina and Mojave, or iOS/iPadOS 14.4. Ensure all devices are running the latest versions to patch this critical vulnerability! You've got this! Follow these steps to protect your devices and stay secure! 🛡️

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.07002 · 93.7th percentile
Published
2021-04-02T18:06Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 02 APR 18:06Z
    A logic issue was addressed with improved restrictions
    cvelistv5